CVE-2020-12013: SQL Injection
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-12013?
CVE-2020-12013 is a vulnerability that allows for the execution of certain arbitrary SQL commands on Mitsubishi Electric MC Works64 Version 4.02C and earlier, and Mitsubishi Electric MC Works32 Version 3.00A.
How severe is CVE-2020-12013?
CVE-2020-12013 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2020-12013?
CVE-2020-12013 affects Mitsubishi Electric MC Works64 Version 4.02C and earlier, and Mitsubishi Electric MC Works32 Version 3.00A.
Are there any known fixes for CVE-2020-12013?
At the moment, there are no known fixes for CVE-2020-12013. It is recommended to follow the guidance provided by the software vendor or CERT/CSIRT.
Where can I get more information about CVE-2020-12013?
You can find more information about CVE-2020-12013 on the official website of CERT/CSIRT.